Documentation
¶
Overview ¶
Package runner starts pnpm and Trivy as subprocesses: it writes their input files, runs the binary, and gives the caller the combined output.
Index ¶
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
This section is empty.
Types ¶
type Credential ¶
Credential identifies the uid and gid a child process runs as. A nil Credential leaves the child under the caller's own identity, the case outside the container.
type Pnpm ¶
type Pnpm interface {
Resolve(ctx context.Context, in ResolveInput) (ResolveResult, error)
}
Pnpm resolves a package.json into a pnpm-lock.yaml without installing anything, so a resolution only pays for registry metadata.
type PnpmCLI ¶
type PnpmCLI struct {
// contains filtered or unexported fields
}
PnpmCLI resolves dependencies by running the pnpm CLI through Node.js, the packaging pnpm ships.
func NewPnpmCLI ¶
func NewPnpmCLI(bin, cacheDir string, asUser *Credential) *PnpmCLI
NewPnpmCLI builds a PnpmCLI. bin is the path to pnpm's own entry point, <pnpm dir>/package/bin/pnpm.cjs, run through node. cacheDir holds pnpm's content store and registry metadata cache. asUser is nil outside the container.
func (*PnpmCLI) Resolve ¶
func (c *PnpmCLI) Resolve(ctx context.Context, in ResolveInput) (ResolveResult, error)
Resolve writes the manifest and a pnpm-workspace.yaml pinned to in.Target, runs "pnpm install --lockfile-only" and reads the resulting lockfile back. The store and cache sit under cacheDir, so resolutions share downloaded metadata across calls.
type ResolveInput ¶
ResolveInput is a resolution request. Dir is a temporary directory the caller owns; Resolve writes the manifest and workspace file into it and reads pnpm-lock.yaml back from it.
type ResolveResult ¶
type ResolveResult struct {
Lockfile []byte // pnpm-lock.yaml
Output string // combined stdout and stderr, shown to the user on failure
}
ResolveResult is the outcome of a resolution.
type Trivy ¶
type Trivy interface {
// ScanSBOM scans the CycloneDX document at sbomPath and writes a JSON
// report to outPath. It returns the combined output.
ScanSBOM(ctx context.Context, sbomPath, outPath string) (string, error)
// ConvertToCycloneDX converts the JSON report at reportPath into a
// CycloneDX document at outPath. It returns the combined output.
ConvertToCycloneDX(ctx context.Context, reportPath, outPath string) (string, error)
// UpdateDB downloads the vulnerability database. It returns the
// combined output.
UpdateDB(ctx context.Context) (string, error)
}
Trivy scans a CycloneDX document for known vulnerabilities, converts a scan report to CycloneDX, and refreshes the vulnerability database.
type TrivyCLI ¶
type TrivyCLI struct {
// contains filtered or unexported fields
}
TrivyCLI runs the trivy binary.
func NewTrivyCLI ¶
func NewTrivyCLI(bin, cacheDir string, asUser *Credential) *TrivyCLI
NewTrivyCLI builds a TrivyCLI that runs bin with its vulnerability database cache under cacheDir. asUser is nil outside the container.
func (*TrivyCLI) ConvertToCycloneDX ¶
func (c *TrivyCLI) ConvertToCycloneDX(ctx context.Context, reportPath, outPath string) (string, error)
ConvertToCycloneDX converts the JSON report at reportPath into a CycloneDX document at outPath. convert reads an existing report and touches no database, but --cache-dir is a global trivy flag that defaults to a path under HOME regardless of the subcommand; passing it explicitly, as ScanSBOM already does, keeps this from depending on HOME being set to something the caller can write.